Exception Risk Calculator
Score a policy exception or risk acceptance: control bypassed, exposure window, blast radius and compensating controls, with an approval level.
Inputs
Exception Risk Level
Medium
Exception Risk Score
3.00of 5
Share of the Maximum Score
59.9%
Maximum Defensible Window
180days
Required Approval Level
Head of security
Window Verdict
Requested window is proportionate to the risk, and should expire automatically rather than on request
Justification Verdict
Business value is weak relative to the risk: push back and fund the fix rather than renewing the exception again
Step by step
Values used
Criticality of the control being bypassed = 4 — Key control, no alternative; Requested exception window = 90 days; Sensitivity of the data or system in scope = 4 — Personal data; Compensating control strength = 40 %; Systems or endpoints covered by the exception = 12 systems; Any affected system is internet-facing = Yes; Times this exception has already been renewed = 2 renewals; Strength of the business justification = 3 — Delivery deadline
Exception Risk
Exception risk = (0.30 × control criticality + 0.25 × data sensitivity + 0.20 × window band + 0.15 × blast-radius band + 0.10 × internet exposure) × compensating factor × renewal uplift.
Exception Risk Level
= Medium
Exception Risk Score
= 3.00 of 5
Share of the Maximum Score
= 59.9
Maximum Defensible Window
= 180 days
Required Approval Level
= Head of security
Window Verdict
= Requested window is proportionate to the risk, and should expire automatically rather than on request
How it works
Time is treated as a risk factor in its own right, because the same technical gap is a different exposure for thirty days than for three years. Compensating controls reduce the score by at most 60%, and each previous renewal adds an uplift — a permanent exception is not an exception, it is an undocumented change to the policy, and the arithmetic should make that visible. Exception registers are where security debt accumulates quietly, and mapping a score to a named approver and a maximum window is what stops a temporary bypass becoming the architecture. These are management estimates to support consistent decisions, not a compliance determination.
Formula
Exception Risk
Exception risk = (0.30 × control criticality + 0.25 × data sensitivity + 0.20 × window band + 0.15 × blast-radius band + 0.10 × internet exposure) × compensating factor × renewal uplift.
- window band
- 1 for 30 days or less, rising to 5 beyond a year
- blast-radius band
- Systems affected, banded 1–5
- renewal uplift
- +8% per previous renewal, capped at five
Frequently Asked Questions
How is Exception Risk calculated?
Exception risk = (0.30 × control criticality + 0.25 × data sensitivity + 0.20 × window band + 0.15 × blast-radius band + 0.10 × internet exposure) × compensating factor × renewal uplift. Time is treated as a risk factor in its own right, because the same technical gap is a different exposure for thirty days than for three years. Compensating controls reduce the score by at most 60%, and each previous renewal adds an uplift — a permanent exception is not an exception, it is an undocumented change to the policy, and the arithmetic should make that visible.
Why does Exception Risk matter?
Exception registers are where security debt accumulates quietly, and mapping a score to a named approver and a maximum window is what stops a temporary bypass becoming the architecture. These are management estimates to support consistent decisions, not a compliance determination.
What values do I need to enter?
This calculator takes 8 inputs: Criticality of the control being bypassed, Requested exception window, Sensitivity of the data or system in scope, Compensating control strength, Systems or endpoints covered by the exception, Any affected system is internet-facing, Times this exception has already been renewed, Strength of the business justification. The pre-filled defaults are a realistic starting point — replace them with figures from your own environment for a result you can act on.
What should happen when an exception expires?
The control comes back on by default and the exception has to be re-argued with fresh evidence. Exceptions that lapse into silent permanence are the ones that appear in incident reports, and automatic expiry is the only mechanism that reliably prevents it.
Can a compensating control make an exception risk-free?
No, and capping its benefit at 60% is deliberate. A compensating control was designed for a different purpose, is rarely tested against this specific risk, and often shares a dependency with the control being bypassed.
You might also need
- Residual Risk CalculatorCommonly used together
- Audit Finding Severity CalculatorCommonly used together
- Control Gap CalculatorCommonly used together
- Disaster Recovery RTO CalculatorAlso in Compliance & GRC
- Security Investment ROI CalculatorAlso in Compliance & GRC
- ISO 27001 Compliance CalculatorAlso in Compliance & GRC